What's new

Port Scan Results - Router replying to Ping requests

  • SNBForums Code of Conduct

    SNBForums is a community for everyone, no matter what their level of experience.

    Please be tolerant and patient of others, especially newcomers. We are all here to share and learn!

    The rules are simple: Be patient, be nice, be helpful or be gone!

Deadeye

Occasional Visitor
I ran two different port scans from grc.com and received surprising results. The first is that the router shouldn't be replying to WAN ping requests although according to the port scan in the 2nd pic, a reply was sent. Why would this be happening?

How do I stealth the closed ports and why would port 443 be open in that scan?

AC68W running 380.65
Screen Shot 2017-02-06 at 2.36.44 PM.pngScreen Shot 2017-02-06 at 2.29.39 PM.pngScreen Shot 2017-02-06 at 2.33.19 PM.png
 
Per Martinr's posted link, it could be 2 separate problems.

The WAN ping can happen if you have a cable modem or other media translation device in front of your router that does respond to the ping request before it gets to the Asus. In the case of the Comcast provided Arris CMs, they respond to pings and Comcast prevents you from changing that. I experience this one

Paul
 
I am running a VPN not associated with the router so that would explain port 443 being open. Thank you Martinr for the link.

Thanks Paul, I will contact Charter and see if their modem, a Cisco DPC3008, functions the same way.

I am not running Aicloud. I am running AiProtection however. Would that be the reason for the closed vs stealth ports? I'm anticipating that all the ports would be stealth as a normal state for the firewall. Will someone please confirm? Going to do some more testing tonight.


Sent from my iPhone using Tapatalk
 
I heard GRC testing is iffy at best. I pretty sure rmerlin says it's not very good. I wouldn't rely on its results being conclusive enough.
 
I tried 4 different online port scanners and they all detected 443 being open. All the other ports were closed or filtered. One site allowed me to enter specific ports to scan and I took the text output of open ports from GRC and they all came back filtered.

I now feel that GRC was giving me false positives. GRC was a reliable site at one point, however due to this and a previous issue, I have now lost confidence in it.
 
There are free, online nmap scanners. I'd say nmap is the de-facto port scanning standard.
 

Latest threads

Sign Up For SNBForums Daily Digest

Get an update of what's new every day delivered to your mailbox. Sign up here!
Top